Communication via e-mail
An e-mail address is set up for every student for communicating with lecturers and fellow students via e-mail. For more detailed information, please see the ITSC website.
Spam prevention
All e-mails sent from the internet – that is, from external sources – to the Technical University of Applied Sciences Würzburg-Schweinfurt (xxxx@thws.de) first pass through a so-called ‘spam checker’ operated by the University of Würzburg.
The spam checker uses heuristic methods to assess the likelihood of an e-mail being classified as spam and inserts, amongst other things, a line in the following format into the e-mail header:
X-Spam-Level: ******
The more stars shown, the greater the likelihood that the e-mail is spam.
Rule of thumb: More than 5 stars almost always indicate spam.
Many e-mail programmes allow you to set up filter rules to evaluate the line “X-Spam-Level: ...” and move e-mails suspected of being spam to a separate folder or delete them immediately.
Instructions on setting up spam filters in e-mail programmes such as Pine, Pegasus, Mozilla, Eudora and Outlook can be found on this University of Würzburg website.
If you have any further questions, please contact the staff at the Information Technology Centre of the University of Würzburg.
SpamCheck – Quarantine for spam
SpamCheck, based on Sophos’s PureMessage product, provides you with a user-friendly end-user web interface for managing blocked spam e-mails and configuring other basic settings relating to the handling of e-mails sent to your e-mail address.
Please note that the sender will still be notified that all e-mails listed in SpamCheck have not been delivered, even if you retrieve them from the quarantine! If you retrieve spam e-mails from the quarantine, please be aware that, depending on your local settings, your e-mail client may move them to the junk mail folder.
E-mails that have been blocked are held in quarantine. They remain there until they are deleted by the system after 28 days. The following section explains how you will be notified about blocked e-mails, how you can request copies of these blocked e-mails, and how you can disable the blocking function entirely or for specific senders.
Visit the SpamCheck server: https://spamcheck.uni-wuerzburg.de.
Further information can be found on the website of the University of Würzburg.
Encrypting an e-mail
For the sake of simplicity, this section describes the encryption of e-mails sent via MS Outlook between partners who have been issued with a certificate by the FHWS-CA 3 certification authority.
Prerequisites are therefore: a certificate issued by FHWS-CA 3, as described above, and the use of MS Outlook on the THWS Exchange server.
Background information: encryption method
The public key of all users who have completed certification via FHWS-CA 3 is stored on a central server and is automatically loaded by Outlook when an encrypted e-mail is to be sent to a partner.
- Open Outlook
- New e-mail
- Activate the encryption button
Here you will find a description of how to send encrypted e-mails to the extended user group of the DFN-PCA – that is, to all partners who have had certificates issued via the DFN Association – and how to obtain the public key of a 'third-party' partner (outside the DFN-PCA).
Risks of e-mail forwarding to private accounts
There are many reasons why forwarding work-related e-mails to private accounts is highly problematic. In particular, internal, confidential or classified information, such as committee documents and unpublished research findings, must be protected.
The same applies to information covered by data protection legislation, i.e. all personal data, for example from human resources, student or examination administration.
Confidentiality
If e-mails are forwarded to private e-mail accounts, there is no guarantee that the messages and attachments sent will not be viewed, copied or tampered with by external individuals or computer systems.
Employees and civil servants at higher education institutions are bound by a duty of confidentiality.
The duty of confidentiality applies in principle to all matters of which the employee becomes aware whilst on duty or in the course of their duties.
This means that work-related matters must be treated confidentially and protected from unauthorised access. This applies both to outsiders and, in principle, to employees. [*]
For employees of a higher education institution, whether civil servants or not, this results in a prohibition on forwarding work-related e-mails to private e-mail addresses.
Availability
Using work e-mail addresses ensures that e-mails are transmitted via THWS’ internal network and therefore reach the intended recipient promptly.
E-mails that are routed via external e-mail providers leave the internal network and may arrive late or not at all.
There can be many reasons for delayed or even failed delivery:
Example 1: Private providers (e.g. Web.de, GMX, Google, Yahoo, Hotmail) often apply automated spam detection before the inbox and maintain so-called blacklists in which domains (e.g. google.de, yahoo.de) are classified as untrustworthy.
E-mails from these domains are flagged as spam and, in the worst-case scenario, are not delivered at all. If the private e-mail provider has ended up on a blacklist, e-mails sent from there will also no longer be delivered, or only after considerable delays.
Example 2: Private hosting providers often offer limited storage capacity (particularly in their free versions). Once the storage limit has been reached, no further e-mails are delivered. Although work-related e-mails are sent, they cannot be delivered.
Integrity
When e-mails are forwarded to an external e-mail account, they end up with the external hosting provider, to which the ITSC has no access. It is not possible to check whether the account is secure, whether it has been hacked and the password compromised, or whether spam or phishing messages are being sent from that account.
Nor is it possible to verify whether a message really originates from the sender, or whether parts of the message or the entire message have been tampered with.
Support
The ITSC does not provide support for e-mails forwarded to private accounts. If problems arise with the forwarding process or the external hosting provider, the ITSC will not be able to assist.
Conclusion
Forwarding work-related e-mails to private e-mail accounts carries a wide range of risks. We therefore strongly advise against forwarding e-mails. For employees and civil servants, this even constitutes a breach of their employment contract. The use of external hosting providers creates a risk – beyond the University’s control – regarding the confidentiality, integrity and availability of information and resources. Support for external e-mail accounts is not guaranteed.
* For civil servants, the duty of confidentiality is governed by Section 37 of the Civil Service Act (BeamtStG); for employees, by Section 3(2) of the Collective Agreement for the Public Service of the Federal States (TV-L).
